Skip to content

Commit 1d82cd7

Browse files
authored
Merge pull request #105166 from TerryLanfear/Feb2120
Feb2120
2 parents 41a8430 + e94600e commit 1d82cd7

File tree

1 file changed

+17
-17
lines changed

1 file changed

+17
-17
lines changed

articles/security/fundamentals/customer-lockbox-overview.md

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
---
22
title: Customer Lockbox for Microsoft Azure
33
description: Technical overview of Customer Lockbox for Microsoft Azure, which provides control over cloud provider access when Microsoft may need to access customer data.
4-
author: cabailey
4+
author: TerryLanfear
55
ms.service: security
66
ms.subservice: security-fundamentals
77
ms.topic: article
8-
ms.author: cabailey
9-
manager: barbkess
8+
ms.author: terrylan
9+
manager: rkarlin
1010
ms.date: 11/04/2019
1111
---
1212

@@ -37,37 +37,37 @@ The following steps outline a typical workflow for a Customer Lockbox request.
3737
- The scope of the resource
3838
- Whether the requester is an isolated identity or using multi-factor authentication
3939
- Permissions levels
40-
40+
4141
Based on the JIT rule, this request may also include an approval from Internal Microsoft Approvers. For example, the approver might be the Customer support lead or the DevOps Manager.
4242

4343
6. When the request requires direct access to customer data, a Customer Lockbox request is initiated. For example, remote desktop access to a customer's virtual machine.
44-
44+
4545
The request is now in a **Customer Notified** state, waiting for the customer's approval before granting access.
4646

4747
7. At the customer organization, the user who has the [Owner role](../../role-based-access-control/rbac-and-directory-admin-roles.md#azure-rbac-roles) for the Azure subscription receives an email from Microsoft, to notify them about the pending access request. For Customer Lockbox requests, this person is the designated approver.
48-
48+
4949
Example email:
50-
50+
5151
![Azure Customer Lockbox - email notification](./media/customer-lockbox-overview/customer-lockbox-email-notification.png)
5252

5353
8. The email notification provides a link to the **Customer Lockbox** blade in the Azure portal. Using this link, the designated approver signs in to the Azure portal to view any pending requests that their organization has for Customer Lockbox:
54-
54+
5555
![Azure Customer Lockbox - landing page](./media/customer-lockbox-overview/customer-lockbox-landing-page.png)
56-
56+
5757
The request remains in the customer queue for four days. After this time, the access request automatically expires and no access is granted to Microsoft engineers.
5858

5959
9. To get the details of the pending request, the designated approver can select the lockbox request from **Pending Requests**:
60-
60+
6161
![Azure Customer Lockbox - view the pending request](./media/customer-lockbox-overview/customer-lockbox-pending-requests.png)
6262

6363
10. The designated approver can also select the **SERVICE REQUEST ID** to view the support ticket request that was created by the original user. This information provides context for why Microsoft Support is engaged, and the history of the reported problem. For example:
64-
64+
6565
![Azure Customer Lockbox - view the support ticket request](./media/customer-lockbox-overview/customer-lockbox-support-ticket.png)
6666

6767
11. After reviewing the request, the designated approver selects **Approve** or **Deny**:
68-
68+
6969
![Azure Customer Lockbox - select Approve or Deny](./media/customer-lockbox-overview/customer-lockbox-approval.png)
70-
70+
7171
As a result of the selection:
7272
- **Approve**: Access is granted to the Microsoft engineer. The access is granted for a default period of eight hours.
7373
- **Deny**: The elevated access request by the Microsoft engineer is rejected and no further action is taken.
@@ -108,13 +108,13 @@ For scenarios that involve remote desktop access, you can use Windows event logs
108108

109109
The following services are now currently in preview for Customer Lockbox:
110110

111-
- Azure Storage
111+
- Azure Storage
112112

113-
- Azure SQL DB
113+
- Azure SQL DB
114114

115-
- Azure Data Explorer
115+
- Azure Data Explorer
116116

117-
- Virtual machines (now also covering access to memory dumps and managed disks)
117+
- Virtual machines (now also covering access to memory dumps and managed disks)
118118

119119
- Azure subscription transfers
120120

0 commit comments

Comments
 (0)